CWE-89
20,793 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CVEs (20,793)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser |
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers |
2Debian Djangoproject2Debian Linux DjangoJun 17, 2026 Apr 12, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options ar...Show more |
2Debian Djangoproject2Debian Linux DjangoJun 17, 2026 Apr 12, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary...Show more |
Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort. When leveraging the following together: Elide Aggregation Data Store for Analytic Queries, Parameterized Columns (A colum...Show more |
JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice architectures. SQL Injection vulnerability in entities for applications generated with the option "reactive...Show more |
An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php. |
1Secondlinethemes 1Podcast Importer Secondline Jun 17, 2026 Apr 11, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file |
1Elbtide 1Advanced Booking Calendar Jun 17, 2026 Apr 11, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks |
1Stopbadbots 1Block And Stop Bad Bots Jun 17, 2026 Apr 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the...Show more |
Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases. |
zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php/ajax.php. |
zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php. |
An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php. |
1Movie Seat Reservation Project 1Movie Seat Reservation Jun 17, 2026 Apr 8, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter. |
1Car Rental System Project 1Car Rental System Jun 17, 2026 Apr 8, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter. |
1Phpgurukul 1Zoo Management System Jun 17, 2026 Apr 8, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter. |
1Online Banking System Project 1Online Banking System Jun 17, 2026 Apr 8, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Online Banking System in PHP v1 was discovered to contain multiple SQL injection vulnerabilities at /staff_login.php via the Staff ID and Staff Password parameters. |
SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data |
ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An unauthenticated LAN attacker to inject arbitrary SQL code to read, modify and delete database. |